Cybersecurity

Is Your Period Tracker App Safe After Roe v. Wade?

Is Your Period Tracker App Safe After Roe v. Wade?
Illustration · Newzlet

Updated 21 August 2026 — this article was rewritten with primary sources added and unsupported claims removed.

Since the Supreme Court overturned Roe v. Wade in its 2022 Dobbs decision, one question about period-tracking apps has real stakes: can the data be used against you? We reviewed the FTC’s enforcement record and compared how the mainstream apps handle your data against the privacy-first alternatives. Here are straight answers.

Did period apps actually share this data?

Yes — provably, in at least one major case. The Federal Trade Commission found that Flo, whose Period & Ovulation Tracker had millions of users, shared sensitive health data — including when a user was menstruating or intended to get pregnant — with Facebook, Google, and other firms, despite promising to keep it private. Flo settled; the finalized 2021 order requires it to obtain affirmative consent before sharing health data and to tell third parties that received the data to destroy it (Federal Trade Commission). The case matters less as one company’s misstep than as proof that “we keep it private” and what actually happens to the data can be two different things.

Doesn’t a health-privacy law cover this?

Not the one most people assume. HIPAA binds health providers, plans, and their business associates — categories defined in the regulation itself (45 CFR § 160.103). A period app you downloaded is none of those, so the cycle data you type into it sits outside HIPAA entirely. A handful of states have started to fill the gap — Washington’s My Health My Data Act is the strongest — but if you don’t live in one, your statutory protection is thin.

Could it really be used against me?

The concrete risk is legal process, not marketing. Data an app stores on its own servers, or shares with third parties, can be requested through a subpoena or court order — a sharper concern in states that restrict or criminalise abortion after Dobbs. The exposure is not that an app “reports” you; it is that your intimate reproductive timeline exists somewhere a court can reach. The way to shrink that risk is to make sure it exists in as few places as possible.

The gap this sits in is not specific to menstrual data. It is the same one that leaves heart-rate and sleep data from a wearable outside HIPAA entirely, and that state legislatures have begun patching one category at a time — Virginia, for instance, by banning the sale of precise location data. Location matters here too: automated licence-plate readers have already been queried in searches connected to reproductive care.

Which trackers are actually safer?

The safest design is simple: an app that keeps your data only on your phone and never uploads it. Three are consistently singled out for doing exactly that — Drip, Euki, and Periodical all store data locally, share nothing with third parties, and skip location tracking. Euki adds a “duress PIN” that shows a decoy screen if someone forces you to open it (Euki), and Drip is fully open-source, so outside experts can audit its code rather than take its word (Drip); independent reviewers reach the same verdict about the local-only trackers (Mozilla’s *Privacy Not Included). None of these send your cycle to an ad network, and none of them hold a server-side copy for a court to subpoena.

The short version

A mainstream cloud tracker is convenient and, in the wrong state, a liability, because the data leaves your device. A local-only app trades a few sync features for the one property that matters here: there is no remote copy to sell, breach, or subpoena. If reproductive privacy is your concern, that trade is worth making.

AI-Assisted Content — This article was produced with AI assistance. Sources are cited below. Factual claims are verified automatically; uncertain claims are flagged for human review. Found an error? Contact us or read our AI Disclosure.

More in Cybersecurity

See all →